← WordPress Vulnerabilities
WordPress security by component

Appointment Hour Booking

Appointment Hour Booking is a WordPress component with 12 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 7.2.

Plugin slug: appointment-hour-booking

CVE-2026-65514: Appointment Hour Booking: Cross-site scripting

Appointment Hour Booking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.5.86.

PublishedJul 23, 2026
Known safe version1.5.87
Safe version
Jul 23, 2026 CVE-2026-65514
Appointment Hour Booking: Cross-site scripting
Appointment Hour Booking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 1.5.86.
1.5.87
CVE6.5
NVDPending
Jan 28, 2026 CVE-2026-1083
Appointment Hour Booking – Booking Calendar: Cross-site scripting
Appointment Hour Booking – Booking Calendar is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVDPending
Jan 02, 2025 CVE-2023-45649
Appointment Hour Booking: A security weakness
Appointment Hour Booking is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
May 17, 2024 CVE-2024-32720
Appointment Hour Booking: A security weakness
Appointment Hour Booking is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 29, 2022 CVE-2022-4036
Appointment Hour Booking: A security weakness
Appointment Hour Booking is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Nov 29, 2022 CVE-2022-4035
Appointment Hour Booking: A security weakness
Appointment Hour Booking is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD6.1
Nov 29, 2022 CVE-2022-4034
Appointment Hour Booking: A security weakness
Appointment Hour Booking is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.8
NVD7.8
Nov 18, 2022 CVE-2022-41692
Appointment Hour Booking: A security weakness
Appointment Hour Booking is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Jun 13, 2022 CVE-2022-1710
Appointment Hour Booking: Cross-site scripting
Appointment Hour Booking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Oct 11, 2021 CVE-2021-24712
Appointment Hour Booking: A security weakness
Appointment Hour Booking is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Oct 04, 2021 CVE-2021-24673
Appointment Hour Booking: Cross-site scripting
Appointment Hour Booking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 11, 2019 CVE-2019-13505
Appointment Hour Booking: Cross-site scripting
Appointment Hour Booking is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1